NIS2 requirements for software suppliers
Customers in NIS2 scope pass the requirements to their software suppliers through questionnaires and contracts. ELASTO answers them with evidence and closes the gaps they expose.
The request, on one sheet
- Legal basis
- Article 21, supply chain
- Sent by
- Customers in NIS2 scope
- Sent to
- Suppliers, in scope or not
- Arrives as
- A questionnaire, then clauses
- Answered with
- Settings, records, files
Supplier security under NIS2: how the requirement travels
A customer in scope proves supply chain security with its suppliers' evidence.
Why suppliers outside scope get pulled in
Article 21 makes supply chain security a minimum measure for every entity in scope, and asks each one to weigh the vulnerabilities of its direct suppliers, the quality of their products and their security practices, including secure development.
A customer can only show that work with evidence from the supplier. The first sign is usually a questionnaire, followed by contract clauses on incident notice, subcontractors and audit rights.
Suppliers in scope themselves
Managed service providers and managed security service providers sit in Annex I under ICT service management, so a mid-size or large software company that runs systems for its customers carries NIS2 duties directly.
NIS2 security questionnaire: the questions and the evidence
The wording changes; the topics repeat.
53of 61
The rest go on the fix list
In every questionnaire
Eight topics and the evidence behind each
- Incident notice
- Asked: how fast the supplier reports an incident that affects the customer, and to whom. Evidence: an incident runbook with a contact list, and the notification time written into the contract.
- MFA
- Asked: whether every staff and admin account uses multi-factor authentication. Evidence: an enforcement report exported from the identity provider.
- Backups
- Asked: how often data is backed up and whether restores work. Evidence: a restore test record with the date, the data set and the time it took.
- Subcontractors
- Asked: which third parties touch the customer's data, and where. Evidence: a subprocessor list with location, purpose and the data each one receives.
- Vulnerability handling
- Asked: how vulnerabilities are found, fixed and disclosed. Evidence: dependency scan output, a patch record and a published disclosure contact in security.txt.
- SBOM
- Asked: which open source and third-party components ship in the product. Evidence: a machine-readable SBOM per release, in SPDX or CycloneDX format.
- Secure development
- Asked: how code is reviewed, tested and deployed. Evidence: branch protection settings, CI checks and a secrets policy.
- Access control
- Asked: who can reach production, and how leavers lose access. Evidence: an access list, offboarding records and a periodic access review.
Cyber Resilience Act vs NIS2 for software products
The CRA regulates products; NIS2 regulates organisations. A software company can face both.
10 December 2024
Entry into force
Law, with most duties still ahead.11 September 2026
Reporting duties
Exploited vulnerabilities go to ENISA within 24 hours.11 December 2027
Full application
CE marking and an SBOM for each product.
Where SaaS sits under the CRA
Pure SaaS usually falls outside the CRA unless it serves as the remote data processing of a product. The line depends on the product, so each case gets read against the text.
Last checked 28 September 2026, against Regulation (EU) 2024/2847.
NIS2 questionnaire review: answer, fix, set up
The questionnaire answered, the gaps closed and the evidence kept for the next one.
Answer
Every answer backed by a file, or given a fix date.Fix
Gaps closed by risk: MFA, restore tests, an SBOM, patches.Set up
An evidence folder kept current for the next customer.
ELASTO's own answers, as a supplier
ELASTO is a software supplier too. The security and disclosure page sets out how a vulnerability report reaches the studio, what happens to it and the measures behind this site.
On Mozar, where ELASTO is the software supplier, the same evidence is built into the platform. New web platforms ELASTO builds start from the same practices.
NIS2 for suppliers outside the EU
NIS2 does not bind a UK or North American company directly. Its EU customers still carry Article 21, so the questionnaire and the contract clauses arrive in the same way, and the evidence that answers them is identical. ELASTO works in English, Romanian and French from Cluj-Napoca, inside the EU.
NIS2 supplier questions
A customer's NIS2 questionnaire: where to start
A customer's NIS2 questionnaire starts with an inventory of what already exists: MFA settings, backup records, the subprocessor list, the patch process. Answers backed by evidence go first; the rest get their current status and a fix date. A dated plan holds up better than an unsupported yes.
NIS2 requirements for suppliers
NIS2 sets no separate list of supplier requirements. Suppliers get asked about the Article 21 measures their customers must run, mostly incident notice, MFA, backups, vulnerability handling, secure development and subcontractors. The contract then turns those answers into obligations, such as a notification deadline.
Suppliers outside the EU or outside NIS2 scope
The directive puts no direct duty on them. Their customers in scope carry it, and Article 21 makes them assess supplier practices, so the requirements arrive through questionnaires and contracts. For many customers, the answers decide whether a supplier stays on the approved vendor list.
NIS2 and SaaS providers
A SaaS provider falls under NIS2 directly when the annexes list its activity, for example cloud computing or managed services, and it is mid-size or large. Most SaaS vendors are not in scope themselves and meet NIS2 through their customers' questionnaires.
Cyber Resilience Act or NIS2 for a software product
The Cyber Resilience Act applies to software sold as a product in the EU; NIS2 applies to organisations in listed sectors and reaches suppliers through contracts. A company that sells an installable product can face both. CRA reporting duties apply from 11 September 2026 and the full requirements from 11 December 2027.
ISO 27001 certificate in place of the questionnaire
An ISO 27001 certificate shortens a NIS2 questionnaire but rarely replaces it. Customers still ask about incident notice times, subcontractors and the SBOM, which a certificate does not answer on its own. Attaching the certificate with its statement of applicability answers the control questions in one step.
The NIS2 gap analysis shows what the certificate leaves open.
NIS2 questionnaire review
The first call starts from the questionnaire itself and the systems it asks about.
- Studio
- Cluj-Napoca, Romania, EU